未知家族病毒分析
扫描结果:
C:\WINDOWS\SMSS.EXE --> 与 Trojan.PSW.LMir 90%相似.
系统活动进程
C:\WINDOWS\SYSTEM32\SMSS.EXE
C:\WINDOWS\SYSTEM32\CSRSS.EXE
C:\WINDOWS\SYSTEM32\WINLOGON.EXE
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\SERVICES.EXE
C:\WINDOWS\SYSTEM32\LSASS.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SMSS.EXE
C:\WINDOWS\SYSTEM32\MSVBVM50.DLL
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCHPG.DLL
D:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCH_AG.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\FSSYNC.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_RMT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCCLIENT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLIPC.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLUTIL.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\RPT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCIFACE.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRLOADER.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRKERNEL.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRSTRING.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_SRV.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_CLNT.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\TEMPFILE.PPL
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\PROGRAM FILES\RACER-NJGD\RACERKP.EXE
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\SYSTEM32\MDIMON.DLL
C:\WINDOWS\SYSTEM32\SPOOL\PRTPROCS\W32X86\MDIPPR.DLL
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
C:\WINDOWS\SYSTEM32\TPHANDLE.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_001.DLL
D:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
D:\PROGRAM FILES\WINRAR\RAREXT.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SHELLEX.DLL
D:\PROGRAM FILES\TENCENT\QQ\QDSHM.DLL
D:\PROGRAM FILES\TENCENT\QQ\MFC42.DLL
C:\WINDOWS\SYSTEM32\NVCPL.DLL
C:\WINDOWS\SYSTEM32\NVRSZHC.DLL
C:\WINDOWS\SYSTEM32\NVSHELL.DLL
C:\PROGRAM FILES\COMMON FILES\ADOBE\SHELL\PSICON.DLL
C:\WINDOWS\SYSTEM32\ALG.EXE
C:\WINDOWS\SYSTEM32\CTFMON.EXE
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
D:\PROGRAM FILES\JJ4\JJSVR4.EXE
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
C:\PROGRAM FILES\RACER-NJGD\RACER.EXE
C:\PROGRAM FILES\RACER-NJGD\RWXRE.DLL
C:\PROGRAM FILES\RACER-NJGD\NSPR4.DLL
C:\PROGRAM FILES\RACER-NJGD\XPCOM.DLL
C:\PROGRAM FILES\RACER-NJGD\NSS3.DLL
C:\PROGRAM FILES\RACER-NJGD\SOFTOKN3.DLL
C:\PROGRAM FILES\RACER-NJGD\GKGFX.DLL
C:\PROGRAM FILES\RACER-NJGD\XPCOM_COMPAT.DLL
C:\PROGRAM FILES\RACER-NJGD\JS3250.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\NECKO.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\UCONV.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\RACER_BASE_COMP.DLL
C:\PROGRAM FILES\RACER-NJGD\RACER_BASE.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\PIPNSS.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\GKLAYOUT.DLL
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\JAR50.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\GKGFXWIN.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\JSDOM.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\XPCOM_COMPAT_C.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\TEXTEDITOR.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\RACER_AD_COMP.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\RACER_NSS4_COMP.DLL
C:\PROGRAM FILES\RACER-NJGD\NSS4.DLL
C:\PROGRAM FILES\RACER-NJGD\WPCAP.DLL
C:\PROGRAM FILES\RACER-NJGD\PTHREADVC.DLL
C:\PROGRAM FILES\RACER-NJGD\PACKET.DLL
C:\PROGRAM FILES\RACER-NJGD\COMPONENTS\RACER_ACCESS_DHCPPLUS.DLL
C:\PROGRAM FILES\RACER-NJGD\DHCPPLUS.DLL
C:\WINDOWS\SYSTEM32\RAVEXT.DLL
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM32\NVSVC32.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
D:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
C:\WINDOWS\SYSTEM32\TPHANDLE.DLL
C:\PROGRAM FILES\COMMON FILES\COLLEGESOFT\SHARE COMPONENTS\TPHANDLE.DLL
D:\PROGRAM FILES\THUNDER NETWORK\THUNDER\COMDLLS\XUNLEIBHO_001.DLL
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
D:\PROGRAM FILES\MICROSOFT OFFICE\OFFICE11\MSOHEV.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCHPG.DLL
D:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCH_AG.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\FSSYNC.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_RMT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCCLIENT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLIPC.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLUTIL.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\RPT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCIFACE.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRLOADER.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRKERNEL.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRSTRING.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_SRV.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_CLNT.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\TEMPFILE.PPL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
C:\WINDOWS\SYSTEM32\MACROMED\FLASH\FLASH8B.OCX
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORIE.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSVCR71.DLL
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\MSCORLD.DLL
C:\WINDOWS\DOWNLOADED PROGRAM FILES\OL2005.DLL
C:\WINDOWS\SYSTEM32\PYJJ4.IME
D:\PROGRAM FILES\RISING\RAV\RAV.EXE
D:\PROGRAM FILES\RISING\RAV\PLUGIN\RSPGSCAN.DLL
D:\PROGRAM FILES\RISING\RAV\RSAPPMGR.DLL
D:\PROGRAM FILES\RISING\RAV\CFGDLL.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMX.DLL
D:\PROGRAM FILES\RISING\RAV\RAVUI.DLL
D:\PROGRAM FILES\RISING\RAV\RSGUILIB.DLL
D:\PROGRAM FILES\RISING\RAV\PNGDLL.DLL
D:\PROGRAM FILES\RISING\RAV\RSCOMMON.DLL
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
D:\PROGRAM FILES\RISING\RAV\SCANNER.DLL
D:\PROGRAM FILES\RISING\RAV\BWLIST.DLL
D:\PROGRAM FILES\RISING\RAV\RAVUIMSG.DLL
C:\WINDOWS\SYSTEM32\WDMAUD.DRV
C:\WINDOWS\SYSTEM32\MSACM32.DRV
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCHPG.DLL
D:\PROGRAM FILES\RISING\RAV\RAVSCRCH.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\SCRCH_AG.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\FSSYNC.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_RMT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCCLIENT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLIPC.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KLUTIL.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\RPT.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\CCIFACE.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRLOADER.DLL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRKERNEL.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PRSTRING.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_SRV.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\PR_CLNT.PPL
D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\TEMPFILE.PPL
C:\WINDOWS\SYSTEM32\CONIME.EXE
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
E:\下载程序\RSDETECT.EXE
C:\WINDOWS\SYSTEM32\32IEXPLORE.DLL
普通自启动项
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
IMJPMIG8.1 = ; C:\WINDOWS\IME\IMJP8_1\IMJPMIG.EXE /SPOIL /REMADVDEF /MIGRATION32
PHIME2002ASync = ; C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A = ; C:\WINDOWS\SYSTEM32\IME\TINTLGNT\TINTSETP.EXE /IMENAME
SoundMan = ; SOUNDMAN.EXE
Super Rabbit SRRestore = ; D:\PROGRAM FILES\SUPER RABBIT\MAGICSET\SRREST.EXE /AUTOSAVE
helper.dll = ; C:\WINDOWS\SYSTEM32\RUNDLL32.EXE C:\PROGRA~1\3721\HELPER.DLL,RUNDLL32
RavTask = "D:\PROGRAM FILES\RISING\RAV\RAVTASK.EXE" -SYSTEM
StormCodec_Helper = ; "D:\PROGRAM FILES\RINGZ STUDIO\STORM CODEC\STORMSET.EXE" /S /OPTI
SunJavaUpdateSched = ; C:\PROGRAM FILES\JAVA\J2RE1.4.2_03\BIN\JUSCHED.EXE
KernelFaultCheck = C:\WINDOWS\SYSTEM32\DUMPREP 0 -K
IMSCMig = C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40A\IMSCMIG.EXE /PRELOAD
TProgram = ; C:\WINDOWS\SMSS.EXE
NvMediaCenter = ; RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVMCTRAY.DLL,NVTASKBARINIT
RavScanBD = "D:\PROGRAM FILES\RISING\RAV\SCANBD.EXE" /INST
KAVPersonal50 = "D:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS PERSONAL\KAV.EXE" /MINIMIZE
NvCplDaemon = ; RUNDLL32.EXE C:\WINDOWS\SYSTEM32\NVCPL.DLL,NVSTARTUP
RfwMain = "D:\PROGRAM FILES\RISING\RFW\RFWMAIN.EXE" -STARTUP
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
ctfmon.exe = C:\WINDOWS\SYSTEM32\CTFMON.EXE
MSMSGS = ; "C:\PROGRAM FILES\MESSENGER\MSMSGS.EXE" /BACKGROUND
pyjj = D:\PROGRAM FILES\JJ4\JJSVR4.EXE
pbmini = ; C:\PROGRAM FILES\PCAST\PODCASTBARMINI\PODCASTBARMINISTATER.EXE
eMuleAutoStart = ; E:\PROGRAM FILES\EMULE\EMULE.EXE -AUTOSTART
AppInit_DLLs
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs =